IDOR - Delete all Licenses and certifications from users account using CreateOrUpdateHackerCertification GraphQL query
Program: hackerone
Bug Type: IDOR
Bounty: 12500
Date: 2023-08-24
IDOR
sensitive-data
Summary
A Researcher found a vulnerability in a graphql endpoint that allows a attacker to delete Licenses and Certifications stored in the profile with guessable ID. A range of data - licenses and certifications can also be deleted by specifying a range value with the guessable ID.